Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

chore(container)!: Update pulumi-kubernetes-operator Docker tag to v2 #5245

Open
wants to merge 1 commit into
base: main
Choose a base branch
from

Conversation

budimanjojo-bot[bot]
Copy link
Contributor

@budimanjojo-bot budimanjojo-bot bot commented Feb 19, 2025

This PR contains the following updates:

Package Update Change
pulumi-kubernetes-operator major 0.8.1 -> 2.0.0

Release Notes

pulumi/pulumi-kubernetes-operator (pulumi-kubernetes-operator)

v2.0.0

Compare Source

  • Sample network policies #​839
  • Removed obsolete examples #​838
  • Updated documentation and quickstart script #​837

Configuration

📅 Schedule: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Renovate Bot.

@budimanjojo-bot budimanjojo-bot bot added renovate/container Pull request to a Renovate container update renovatebot Pull request created by Renovate type/major Pull request of type major version bump labels Feb 19, 2025
@budimanjojo-bot
Copy link
Contributor Author

--- HelmRelease: infra-system/pulumi-kubernetes-operator Role: infra-system/pulumi-kubernetes-operator

+++ HelmRelease: infra-system/pulumi-kubernetes-operator Role: infra-system/pulumi-kubernetes-operator

@@ -1,102 +0,0 @@

----
-apiVersion: rbac.authorization.k8s.io/v1
-kind: Role
-metadata:
-  name: pulumi-kubernetes-operator
-  labels:
-    app.kubernetes.io/name: pulumi-kubernetes-operator
-    app.kubernetes.io/instance: pulumi-kubernetes-operator
-    app.kubernetes.io/managed-by: Helm
-rules:
-- apiGroups:
-  - ''
-  resources:
-  - pods
-  - services
-  - services/finalizers
-  - endpoints
-  - persistentvolumeclaims
-  - events
-  - configmaps
-  - secrets
-  verbs:
-  - create
-  - delete
-  - get
-  - list
-  - patch
-  - update
-  - watch
-- apiGroups:
-  - apps
-  resources:
-  - deployments
-  - daemonsets
-  - replicasets
-  - statefulsets
-  verbs:
-  - create
-  - delete
-  - get
-  - list
-  - patch
-  - update
-  - watch
-- apiGroups:
-  - monitoring.coreos.com
-  resources:
-  - servicemonitors
-  verbs:
-  - get
-  - create
-- apiGroups:
-  - apps
-  resourceNames:
-  - pulumi-kubernetes-operator
-  resources:
-  - deployments/finalizers
-  verbs:
-  - update
-- apiGroups:
-  - ''
-  resources:
-  - pods
-  verbs:
-  - get
-- apiGroups:
-  - apps
-  resources:
-  - replicasets
-  - deployments
-  verbs:
-  - get
-- apiGroups:
-  - pulumi.com
-  resources:
-  - '*'
-  verbs:
-  - create
-  - delete
-  - get
-  - list
-  - patch
-  - update
-  - watch
-- apiGroups:
-  - coordination.k8s.io
-  resources:
-  - leases
-  verbs:
-  - create
-  - get
-  - list
-  - update
-- apiGroups:
-  - source.toolkit.fluxcd.io
-  resources:
-  - '*'
-  verbs:
-  - get
-  - list
-  - watch
-
--- HelmRelease: infra-system/pulumi-kubernetes-operator RoleBinding: infra-system/pulumi-kubernetes-operator

+++ HelmRelease: infra-system/pulumi-kubernetes-operator RoleBinding: infra-system/pulumi-kubernetes-operator

@@ -1,18 +0,0 @@

----
-apiVersion: rbac.authorization.k8s.io/v1
-kind: RoleBinding
-metadata:
-  name: pulumi-kubernetes-operator
-  labels:
-    app.kubernetes.io/name: pulumi-kubernetes-operator
-    app.kubernetes.io/instance: pulumi-kubernetes-operator
-    app.kubernetes.io/managed-by: Helm
-roleRef:
-  apiGroup: rbac.authorization.k8s.io
-  kind: Role
-  name: pulumi-kubernetes-operator
-subjects:
-- kind: ServiceAccount
-  name: pulumi-kubernetes-operator
-  namespace: infra-system
-
--- HelmRelease: infra-system/pulumi-kubernetes-operator Deployment: infra-system/pulumi-kubernetes-operator

+++ HelmRelease: infra-system/pulumi-kubernetes-operator Deployment: infra-system/pulumi-kubernetes-operator

@@ -1,83 +0,0 @@

----
-apiVersion: apps/v1
-kind: Deployment
-metadata:
-  name: pulumi-kubernetes-operator
-  labels:
-    app.kubernetes.io/name: pulumi-kubernetes-operator
-    app.kubernetes.io/instance: pulumi-kubernetes-operator
-    app.kubernetes.io/managed-by: Helm
-spec:
-  replicas: 1
-  strategy:
-    type: null
-  selector:
-    matchLabels:
-      app.kubernetes.io/name: pulumi-kubernetes-operator
-      app.kubernetes.io/instance: pulumi-kubernetes-operator
-      app: pulumi-kubernetes-operator
-      release: pulumi-kubernetes-operator
-  template:
-    metadata:
-      labels:
-        name: pulumi-kubernetes-operator
-        app: pulumi-kubernetes-operator
-        release: pulumi-kubernetes-operator
-        app.kubernetes.io/name: pulumi-kubernetes-operator
-        app.kubernetes.io/instance: pulumi-kubernetes-operator
-    spec:
-      containers:
-      - args:
-        - --zap-level=error
-        - --zap-time-encoding=iso8601
-        env:
-        - name: WATCH_NAMESPACE
-          valueFrom:
-            fieldRef:
-              fieldPath: metadata.namespace
-        - name: POD_NAME
-          valueFrom:
-            fieldRef:
-              fieldPath: metadata.name
-        - name: OPERATOR_NAME
-          value: pulumi-kubernetes-operator
-        - name: GRACEFUL_SHUTDOWN_TIMEOUT_DURATION
-          value: 5m
-        - name: MAX_CONCURRENT_RECONCILES
-          value: '10'
-        - name: PULUMI_INFER_NAMESPACE
-          value: '1'
-        - name: KUBERNETES_CLUSTER_DOMAIN
-          value: cluster.local
-        image: docker.io/pulumi/pulumi-kubernetes-operator:v1.16.0
-        imagePullPolicy: IfNotPresent
-        name: pulumi-kubernetes-operator
-        securityContext:
-          allowPrivilegeEscalation: false
-          capabilities:
-            drop:
-            - ALL
-          privileged: false
-          runAsGroup: 10003
-          runAsNonRoot: true
-          seccompProfile:
-            type: RuntimeDefault
-        resources:
-          limits:
-            cpu: 500m
-            memory: 5123Mi
-          requests:
-            cpu: 100m
-            memory: 128Mi
-        volumeMounts:
-        - mountPath: /tmp
-          name: tmp-dir
-      serviceAccountName: pulumi-kubernetes-operator
-      terminationGracePeriodSeconds: 300
-      securityContext:
-        fsGroup: 1000
-        runAsUser: 1000
-      volumes:
-      - emptyDir: {}
-        name: tmp-dir
-
--- HelmRelease: infra-system/pulumi-kubernetes-operator ClusterRole: infra-system/pulumi-kubernetes-operator-controller-manager

+++ HelmRelease: infra-system/pulumi-kubernetes-operator ClusterRole: infra-system/pulumi-kubernetes-operator-controller-manager

@@ -0,0 +1,198 @@

+---
+apiVersion: rbac.authorization.k8s.io/v1
+kind: ClusterRole
+metadata:
+  name: pulumi-kubernetes-operator-controller-manager
+  labels:
+    app.kubernetes.io/name: pulumi-kubernetes-operator
+    app.kubernetes.io/instance: pulumi-kubernetes-operator
+    app.kubernetes.io/managed-by: Helm
+rules:
+- apiGroups:
+  - ''
+  resources:
+  - events
+  verbs:
+  - create
+  - patch
+  - update
+- apiGroups:
+  - ''
+  resources:
+  - secrets
+  verbs:
+  - create
+  - get
+  - list
+  - watch
+- apiGroups:
+  - apps
+  resources:
+  - statefulsets
+  verbs:
+  - create
+  - delete
+  - get
+  - list
+  - patch
+  - update
+  - watch
+- apiGroups:
+  - auto.pulumi.com
+  resources:
+  - updates
+  verbs:
+  - create
+  - delete
+  - get
+  - list
+  - patch
+  - update
+  - watch
+- apiGroups:
+  - auto.pulumi.com
+  resources:
+  - updates/finalizers
+  verbs:
+  - update
+- apiGroups:
+  - auto.pulumi.com
+  resources:
+  - updates/status
+  verbs:
+  - get
+  - patch
+  - update
+- apiGroups:
+  - auto.pulumi.com
+  resources:
+  - workspaces
+  verbs:
+  - create
+  - delete
+  - get
+  - list
+  - patch
+  - update
+  - watch
+- apiGroups:
+  - auto.pulumi.com
+  resources:
+  - workspaces/finalizers
+  verbs:
+  - update
+- apiGroups:
+  - auto.pulumi.com
+  resources:
+  - workspaces/rpc
+  verbs:
+  - use
+- apiGroups:
+  - auto.pulumi.com
+  resources:
+  - workspaces/status
+  verbs:
+  - get
+  - patch
+  - update
+- apiGroups:
+  - ''
+  resources:
+  - pods
+  verbs:
+  - create
+  - delete
+  - get
+  - list
+  - patch
+  - update
+  - watch
+- apiGroups:
+  - ''
+  resources:
+  - services
+  verbs:
+  - create
+  - delete
+  - get
+  - list
+  - patch
+  - update
+  - watch
+- apiGroups:
+  - pulumi.com
+  resources:
+  - programs
+  verbs:
+  - create
+  - delete
+  - get
+  - list
+  - patch
+  - update
+  - watch
+- apiGroups:
+  - pulumi.com
+  resources:
+  - programs/finalizers
+  verbs:
+  - update
+- apiGroups:
+  - pulumi.com
+  resources:
+  - programs/status
+  verbs:
+  - get
+  - patch
+  - update
+- apiGroups:
+  - pulumi.com
+  resources:
+  - stacks
+  verbs:
+  - create
+  - delete
+  - get
+  - list
+  - patch
+  - update
+  - watch
+- apiGroups:
+  - pulumi.com
+  resources:
+  - stacks/finalizers
+  verbs:
+  - update
+- apiGroups:
+  - pulumi.com
+  resources:
+  - stacks/status
+  verbs:
+  - get
+  - patch
+  - update
+- apiGroups:
+  - source.toolkit.fluxcd.io
+  resources:
+  - buckets
+  verbs:
+  - get
+  - list
+  - watch
+- apiGroups:
+  - source.toolkit.fluxcd.io
+  resources:
+  - gitrepositories
+  verbs:
+  - get
+  - list
+  - watch
+- apiGroups:
+  - source.toolkit.fluxcd.io
+  resources:
+  - ocirepositories
+  verbs:
+  - get
+  - list
+  - watch
+
--- HelmRelease: infra-system/pulumi-kubernetes-operator ClusterRole: infra-system/pulumi-kubernetes-operator-edit

+++ HelmRelease: infra-system/pulumi-kubernetes-operator ClusterRole: infra-system/pulumi-kubernetes-operator-edit

@@ -0,0 +1,24 @@

+---
+apiVersion: rbac.authorization.k8s.io/v1
+kind: ClusterRole
+metadata:
+  name: pulumi-kubernetes-operator-edit
+  labels:
+    app.kubernetes.io/name: pulumi-kubernetes-operator
+    app.kubernetes.io/instance: pulumi-kubernetes-operator
+    app.kubernetes.io/managed-by: Helm
+    rbac.authorization.k8s.io/aggregate-to-admin: 'true'
+    rbac.authorization.k8s.io/aggregate-to-edit: 'true'
+rules:
+- apiGroups:
+  - pulumi.com
+  - auto.pulumi.com
+  resources:
+  - '*'
+  verbs:
+  - create
+  - delete
+  - deletecollection
+  - patch
+  - update
+
--- HelmRelease: infra-system/pulumi-kubernetes-operator ClusterRole: infra-system/pulumi-kubernetes-operator-view

+++ HelmRelease: infra-system/pulumi-kubernetes-operator ClusterRole: infra-system/pulumi-kubernetes-operator-view

@@ -0,0 +1,23 @@

+---
+apiVersion: rbac.authorization.k8s.io/v1
+kind: ClusterRole
+metadata:
+  name: pulumi-kubernetes-operator-view
+  labels:
+    app.kubernetes.io/name: pulumi-kubernetes-operator
+    app.kubernetes.io/instance: pulumi-kubernetes-operator
+    app.kubernetes.io/managed-by: Helm
+    rbac.authorization.k8s.io/aggregate-to-admin: 'true'
+    rbac.authorization.k8s.io/aggregate-to-edit: 'true'
+    rbac.authorization.k8s.io/aggregate-to-view: 'true'
+rules:
+- apiGroups:
+  - pulumi.com
+  - auto.pulumi.com
+  resources:
+  - '*'
+  verbs:
+  - get
+  - list
+  - watch
+
--- HelmRelease: infra-system/pulumi-kubernetes-operator ClusterRoleBinding: infra-system/pulumi-kubernetes-operator

+++ HelmRelease: infra-system/pulumi-kubernetes-operator ClusterRoleBinding: infra-system/pulumi-kubernetes-operator

@@ -0,0 +1,18 @@

+---
+apiVersion: rbac.authorization.k8s.io/v1
+kind: ClusterRoleBinding
+metadata:
+  name: pulumi-kubernetes-operator
+  labels:
+    app.kubernetes.io/name: pulumi-kubernetes-operator
+    app.kubernetes.io/instance: pulumi-kubernetes-operator
+    app.kubernetes.io/managed-by: Helm
+roleRef:
+  apiGroup: rbac.authorization.k8s.io
+  kind: ClusterRole
+  name: pulumi-kubernetes-operator-controller-manager
+subjects:
+- kind: ServiceAccount
+  name: pulumi-kubernetes-operator
+  namespace: infra-system
+
--- HelmRelease: infra-system/pulumi-kubernetes-operator Role: infra-system/pulumi-kubernetes-operator-leader-election-role

+++ HelmRelease: infra-system/pulumi-kubernetes-operator Role: infra-system/pulumi-kubernetes-operator-leader-election-role

@@ -0,0 +1,42 @@

+---
+apiVersion: rbac.authorization.k8s.io/v1
+kind: Role
+metadata:
+  name: pulumi-kubernetes-operator-leader-election-role
+  labels:
+    app.kubernetes.io/name: pulumi-kubernetes-operator
+    app.kubernetes.io/instance: pulumi-kubernetes-operator
+    app.kubernetes.io/managed-by: Helm
+rules:
+- apiGroups:
+  - ''
+  resources:
+  - configmaps
+  verbs:
+  - get
+  - list
+  - watch
+  - create
+  - update
+  - patch
+  - delete
+- apiGroups:
+  - coordination.k8s.io
+  resources:
+  - leases
+  verbs:
+  - get
+  - list
+  - watch
+  - create
+  - update
+  - patch
+  - delete
+- apiGroups:
+  - ''
+  resources:
+  - events
+  verbs:
+  - create
+  - patch
+
--- HelmRelease: infra-system/pulumi-kubernetes-operator Role: infra-system/pulumi-kubernetes-operator-token-request-role

+++ HelmRelease: infra-system/pulumi-kubernetes-operator Role: infra-system/pulumi-kubernetes-operator-token-request-role

@@ -0,0 +1,19 @@

+---
+apiVersion: rbac.authorization.k8s.io/v1
+kind: Role
+metadata:
+  name: pulumi-kubernetes-operator-token-request-role
+  labels:
+    app.kubernetes.io/name: pulumi-kubernetes-operator
+    app.kubernetes.io/instance: pulumi-kubernetes-operator
+    app.kubernetes.io/managed-by: Helm
+rules:
+- apiGroups:
+  - ''
+  resources:
+  - serviceaccounts/token
+  resourceNames:
+  - pulumi-kubernetes-operator
+  verbs:
+  - create
+
--- HelmRelease: infra-system/pulumi-kubernetes-operator RoleBinding: infra-system/pulumi-kubernetes-operator-leader-election-rolebinding

+++ HelmRelease: infra-system/pulumi-kubernetes-operator RoleBinding: infra-system/pulumi-kubernetes-operator-leader-election-rolebinding

@@ -0,0 +1,18 @@

+---
+apiVersion: rbac.authorization.k8s.io/v1
+kind: RoleBinding
+metadata:
+  name: pulumi-kubernetes-operator-leader-election-rolebinding
+  labels:
+    app.kubernetes.io/name: pulumi-kubernetes-operator
+    app.kubernetes.io/instance: pulumi-kubernetes-operator
+    app.kubernetes.io/managed-by: Helm
+roleRef:
+  apiGroup: rbac.authorization.k8s.io
+  kind: Role
+  name: pulumi-kubernetes-operator-leader-election-role
+subjects:
+- kind: ServiceAccount
+  name: pulumi-kubernetes-operator
+  namespace: infra-system
+
--- HelmRelease: infra-system/pulumi-kubernetes-operator RoleBinding: infra-system/pulumi-kubernetes-operator-token-request-rolebinding

+++ HelmRelease: infra-system/pulumi-kubernetes-operator RoleBinding: infra-system/pulumi-kubernetes-operator-token-request-rolebinding

@@ -0,0 +1,18 @@

+---
+apiVersion: rbac.authorization.k8s.io/v1
+kind: RoleBinding
+metadata:
+  name: pulumi-kubernetes-operator-token-request-rolebinding
+  labels:
+    app.kubernetes.io/name: pulumi-kubernetes-operator
+    app.kubernetes.io/instance: pulumi-kubernetes-operator
+    app.kubernetes.io/managed-by: Helm
+roleRef:
+  apiGroup: rbac.authorization.k8s.io
+  kind: Role
+  name: pulumi-kubernetes-operator-token-request-role
+subjects:
+- kind: ServiceAccount
+  name: pulumi-kubernetes-operator
+  namespace: infra-system
+
--- HelmRelease: infra-system/pulumi-kubernetes-operator Service: infra-system/pulumi-kubernetes-operator

+++ HelmRelease: infra-system/pulumi-kubernetes-operator Service: infra-system/pulumi-kubernetes-operator

@@ -0,0 +1,24 @@

+---
+apiVersion: v1
+kind: Service
+metadata:
+  name: pulumi-kubernetes-operator
+  labels:
+    app.kubernetes.io/name: pulumi-kubernetes-operator
+    app.kubernetes.io/instance: pulumi-kubernetes-operator
+    app.kubernetes.io/managed-by: Helm
+spec:
+  type: ClusterIP
+  ports:
+  - name: http-fileserver
+    port: 80
+    protocol: TCP
+    targetPort: http-fileserver
+  - name: http-metrics
+    port: 8383
+    targetPort: http-metrics
+    protocol: TCP
+  selector:
+    app.kubernetes.io/name: pulumi-kubernetes-operator
+    app.kubernetes.io/instance: pulumi-kubernetes-operator
+
--- HelmRelease: infra-system/pulumi-kubernetes-operator Deployment: infra-system/pulumi-kubernetes-operator-controller-manager

+++ HelmRelease: infra-system/pulumi-kubernetes-operator Deployment: infra-system/pulumi-kubernetes-operator-controller-manager

@@ -0,0 +1,84 @@

+---
+apiVersion: apps/v1
+kind: Deployment
+metadata:
+  name: pulumi-kubernetes-operator-controller-manager
+  labels:
+    app.kubernetes.io/name: pulumi-kubernetes-operator
+    app.kubernetes.io/instance: pulumi-kubernetes-operator
+    app.kubernetes.io/managed-by: Helm
+spec:
+  replicas: 1
+  strategy:
+    type: RollingUpdate
+  selector:
+    matchLabels:
+      app.kubernetes.io/name: pulumi-kubernetes-operator
+      app.kubernetes.io/instance: pulumi-kubernetes-operator
+  template:
+    metadata:
+      annotations:
+        kubectl.kubernetes.io/default-container: manager
+      labels:
+        app.kubernetes.io/name: pulumi-kubernetes-operator
+        app.kubernetes.io/instance: pulumi-kubernetes-operator
+    spec:
+      containers:
+      - name: manager
+        args:
+        - /manager
+        - --leader-elect
+        - --health-probe-bind-address=:8081
+        - --metrics-bind-address=:8383
+        - --program-fs-adv-addr=pulumi-kubernetes-operator.$(POD_NAMESPACE):80
+        - --zap-log-level=info
+        - --zap-time-encoding=iso8601
+        env:
+        - name: POD_NAMESPACE
+          valueFrom:
+            fieldRef:
+              fieldPath: metadata.namespace
+        - name: POD_SA_NAME
+          valueFrom:
+            fieldRef:
+              fieldPath: spec.serviceAccountName
+        ports:
+        - containerPort: 8383
+          name: http-metrics
+          protocol: TCP
+        - containerPort: 9090
+          name: http-fileserver
+          protocol: TCP
+        image: docker.io/pulumi/pulumi-kubernetes-operator:v2.0.0
+        imagePullPolicy: IfNotPresent
+        securityContext:
+          allowPrivilegeEscalation: false
+          capabilities:
+            drop:
+            - ALL
+        resources:
+          limits:
+            cpu: 200m
+            memory: 128Mi
+          requests:
+            cpu: 200m
+            memory: 128Mi
+        livenessProbe:
+          httpGet:
+            path: /healthz
+            port: 8081
+          initialDelaySeconds: 15
+          periodSeconds: 20
+        readinessProbe:
+          httpGet:
+            path: /readyz
+            port: 8081
+          initialDelaySeconds: 5
+          periodSeconds: 10
+      serviceAccountName: pulumi-kubernetes-operator
+      terminationGracePeriodSeconds: 300
+      securityContext:
+        runAsGroup: 65532
+        runAsNonRoot: true
+        runAsUser: 65532
+

@budimanjojo-bot
Copy link
Contributor Author

--- cluster/apps/infra-system/pulumi-kubernetes-operator/base Kustomization: flux-system/infra-system-pulumi-kubernetes-operator HelmRelease: infra-system/pulumi-kubernetes-operator

+++ cluster/apps/infra-system/pulumi-kubernetes-operator/base Kustomization: flux-system/infra-system-pulumi-kubernetes-operator HelmRelease: infra-system/pulumi-kubernetes-operator

@@ -13,13 +13,13 @@

       chart: pulumi-kubernetes-operator
       interval: 15m
       sourceRef:
         kind: HelmRepository
         name: pulumi-charts
         namespace: flux-system
-      version: 0.8.1
+      version: 2.0.0
   install:
     crds: CreateReplace
     createNamespace: true
     remediation:
       retries: 5
   interval: 15m

@budimanjojo-bot budimanjojo-bot bot force-pushed the renovate/pulumi-kubernetes-operator-2.x branch 25 times, most recently from cf0f274 to 48b2d4a Compare February 26, 2025 19:15
@budimanjojo-bot budimanjojo-bot bot force-pushed the renovate/pulumi-kubernetes-operator-2.x branch 8 times, most recently from 5ca85eb to 5e61f1a Compare February 28, 2025 20:20
Signed-off-by: budimanjojo-bot <111944664+budimanjojo-bot[bot]@users.noreply.github.com>
@budimanjojo-bot budimanjojo-bot bot force-pushed the renovate/pulumi-kubernetes-operator-2.x branch from 5e61f1a to d53fe05 Compare February 28, 2025 22:17
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
renovate/container Pull request to a Renovate container update renovatebot Pull request created by Renovate type/major Pull request of type major version bump
Projects
None yet
Development

Successfully merging this pull request may close these issues.

0 participants